In an era where the world is rapidly advancing towards a cleaner future through decarbonization, Energy Exemplar’s mission lies in ‘Empowering Transformative Energy Decisions’🪫☀️🍃 Founded in 1999 in Adelaide, Australia, our award-winning software portfolio encompassing the modeling and simulation platform PLEXOS®, Aurora, and Adapt2, is trusted by innovative organizations across the globe. Through our technology and people, we strive to enable stakeholders from across the entire energy value chain to revolutionize the energy ecosystem and to collaboratively plan and execute for a sustainable energy future with unprecedented clarity, speed, and innovation.
Senior Security & Compliance Analyst
Location
Worldwide
Posted
1 day ago
Salary
0
Seniority
Senior
Job Description
Senior Security & Compliance Analyst
Energy Exemplar
Role Description Reporting to the VP, Cloud Operations & GRC, the Sr. Security & Compliance Analyst will support the execution and continuous improvement of Energy Exemplar’s security, risk, compliance, vulnerability management, and AI governance programs across cloud and enterprise operations. - Support security and compliance programs aligned with ISO 27001, SOC 1, SOC 2, privacy, and emerging AI governance requirements. - Coordinate and drive vulnerability remediation activities across Engineering, Cloud Operations, IT, and Product teams to ensure remediation within defined EE SLAs. - Track and report security metrics, including MTTR, overdue vulnerabilities, remediation trends, audit findings, and compliance dashboards. - Proactively follow up and escalate unresolved vulnerabilities, audit findings, and compliance gaps. - Support continuous control monitoring, risk assessments, third-party risk management, policy management, access reviews, and audit activities. - Respond to customer security and compliance due diligence requests, audits, and questionnaires. - Support AI governance, security, and compliance initiatives, including assessment of AI-related risks, emerging regulations, and industry standards (e.g., ISO 42001, EU AI Act, privacy requirements). - Assist in evaluating AI-enabled solutions and third-party AI services for security, privacy, compliance, and responsible AI considerations. - Monitor emerging cybersecurity threats, privacy regulations, and industry compliance requirements. - Collaborate with cross-functional teams to drive remediation and continuous improvement initiatives. Qualifications - 6–8 years of experience in Governance, Risk & Compliance (GRC), cybersecurity, information security, or risk management. - Strong understanding of ISO 27001, SOC 1 / SOC 2, GDPR/privacy principles, vulnerability management, and security controls. - Experience in Energy / Utilities sector security and compliance requirements (e.g., CEII or critical infrastructure requirements). - Experience coordinating vulnerability remediation programs, tracking SLA compliance, MTTR metrics, and executive reporting. - Experience supporting audits, customer security reviews, and compliance programs. - Familiarity with emerging AI governance, privacy, and security frameworks (e.g., ISO 42001, EU AI Act, responsible AI principles) preferred. - Strong communication, organizational, stakeholder management, and follow-up skills. - Ability to work independently and proactively drive outcomes across distributed teams. Requirements - Preferred Certifications: CISSP, CISA, ISO 27001 Lead Implementer/Auditor, or similar certifications. - AI governance/privacy certifications are a plus. Benefits - Energy Exemplar is proud to be an equal opportunity employer. - We celebrate diversity and are committed to creating an inclusive environment for all team members. - We welcome applications from people of all backgrounds, experiences, identities, and abilities. - Please let us know if you require accommodations at any stage of the recruitment process—we're here to support you in showcasing your full potential.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Champion and execute the overall corporate IT security strategy, roadmap and governance structure, partnering with internal risk/compliance, operational, clinical, technical and business teams as well as external customers and relevant third-party stakeholders • Understand business processes and information system requirements and the associated information risk in those processes • Liaise closely with internal Canadian legal/privacy team to ensure adherence and alignment with Canadian privacy, data governance and regulatory requirements, and the business’ contractual commitments • Work directly with the Canadian commercial team and client base to understand market business and functional requirements and provide compliance, security, and risk assessment support and guidance as required • Establish and execute formal vendor security assessments, including pre-onboarding due diligence and ongoing monitoring of third-party vendors and sub-processors handling sensitive information • Implement all information security, including security breaches, business continuity, and regulatory compliance programs including legal requirements, industry regulations, and best practices (e.g., ISO27001, SOC 2 Type II, etc.) • Lead end-to-end SOC 2 Type II and ISO 27001 audit cycles, including gap assessments, evidence collection via GRC tooling (e.g. Vanta) and act as the primary liaison for external auditors to support certifications • Develop information security guidelines, procedures, and responsibilities and support the development and implementation of technical and administrative security controls and related training and education • Oversee technical incident response planning and implementation and participate in incident response, root cause analysis, and remediation activities • Assess our technology environment and development methodology (SDLC) to identify and mitigate risks and gaps related to information security including potential data breaches • Design, implement, and maintain security controls across infrastructure, applications, integrations and cloud environments in collaboration with our technology team and third-party vendors including: Applications and other systems and middleware components, including operating systems, web servers, databases, and DNS services (e.g. Salesforce, Mulesoft, APIs, etc.) • Network security architecture, including firewalls, segmentation, and secure communication protocols • Logging and monitoring security needs, including SIEM platforms • Encryption standards needed for compliance • Document security configurations, processes, and controls • Digital certificate lifecycle management, including issuance, renewal, and revocation • Communicate information security and compliance risks to leadership and other technical and non-technical stakeholders for proper awareness and decision making • Other duties as assigned
AI Security Engineer – GRC
SCANSCAN is a mission-driven organization that is tackling some of the biggest issues in health care for older adults.
• AI Vendor & Technology Evaluation • Secure AI Implementation Guidance for Development Teams • AI Risk Management & Compliance • Security Integration Reviews • Training , Awareness & Policy
Security Sales Solutions Specialist
CybitCybit is the one-stop-shop for digital transformation that scales in line with your growth
• Own and deliver security revenue targets across new and existing customers • Identify, qualify, and progress cybersecurity opportunities within the pipeline • Lead complex sales cycles, from discovery through to negotiation and closure • Develop and execute account-level security growth plans with Account Managers • Engage senior stakeholders (CIO, CTO, CISO) on cybersecurity strategy and risk • Conduct consultative discovery to uncover business risks, compliance needs, and technical gaps • Position tailored solutions aligned to customer outcomes (risk reduction, compliance, resilience) • Present and demonstrate cybersecurity solutions in a clear, business-relevant manner • Maintain deep knowledge of cybersecurity domains, including: Managed Security Services (SOC, MDR, SIEM), Endpoint and network security, Identity and access management, Cloud security and zero trust architectures, Governance, risk, and compliance (GRC) • Collaborate with pre-sales and technical teams to design high-quality solutions • Work closely with Account Managers to drive joint opportunities, Marketing on campaigns, events, and go-to-market initiatives, and delivery teams to ensure smooth transition from sale to implementation. • Build strong relationships with strategic security vendors • Leverage partner programmes, incentives, and technical resources • Stay current on vendor roadmaps and emerging technologies
Adversarial Task Writer, AI Security, RL Gyms
SD SolutionsCreate exceptional products with passionate people
• You design prompt injection scenarios in YAML, run them against frontier models, validate success rates, and submit passing tasks. • 5 high-quality tasks per week (full-time equivalent).




